Privacypolicy
What UCNHUB LLC collects when you visit ucnhub.com or send us a brief, what we do with it, how long we keep it, and the rights you have over it.
Who We Are
The company behind UCN Hub, and how to reach us about privacy.
UCN Hub is the software studio operated by UCNHUB LLC, a limited liability company formed under the laws of the State of Delaware, United States. Where this policy says “we”, “us”, or “UCN Hub”, it means UCNHUB LLC.
For the personal data described here, UCNHUB LLC is the entity that decides why and how it is processed, except during a client engagement where we act on your instructions — see Our Two Roles.
We have not appointed a Data Protection Officer, as we are not required to. Privacy questions go to the address below and are handled by the people who run the company.
- Legal entity
- UCNHUB LLC
- Entity type
- Delaware limited liability company
- File number
- 10710550
- Registered office
- 254 Chapman Rd, Suite 101-B
Newark, DE 19702, United States - Privacy contact
- [email protected]
Scope of This Policy
What it covers, and what it does not.
This policy applies to ucnhub.com and its subdomains: the pages you read, the enquiry form you may send us, and the correspondence that follows.
It is deliberately narrow, because this site is narrow. There are no user accounts, no dashboard, no payments taken on the site, and nothing for you to log into.
What this policy does not cover
UCN Mail (ucnmail.com) and UCN VPN (ucnvpn.com) are separate services with their own privacy policies, accepted when you create an account with them. Shared corporate ownership does not put them under this document. Sites we link to are likewise governed by their own policies.
Client project data
If you engage us to build software, we may process personal data held in your systems. In that situation you are the controller and we act as your processor — see Client and Project Data. The terms of that processing live in a Data Processing Agreement, not in this policy.
If you are not a client
You do not have to be a customer for this policy to apply to you. Reading the site or sending a single enquiry is enough, and the rights described below are available to you either way.
Our Two Roles
Controller for this site, processor during an engagement.
Data protection law separates the party that decides why data is processed (the controller) from the party that processes it on someone else's instructions (the processor). We are both, depending on the context.
We are the controller of site and enquiry data
The name, email address, and brief you send through the form, the correspondence that follows, our engagement and billing records, and the technical data generated when you request a page. We decide what is collected and why, and this policy is our notice to you about it.
We are a processor of client project data
Personal data inside a client's systems that we touch while building or maintaining software for them. The client decides what that data is and why it exists; we act on their documented instructions and delete or return it at the end of the engagement.
Note
The distinction has a practical consequence. If you ask us to delete an enquiry you sent, we act on it directly. If you ask us to delete personal data about you that sits inside a client's product we happen to have built, we will refer you to that client, because the decision is theirs and not ours to make.
Information We Collect
The complete list.
We collect very little, because a marketing site with one form does not need much. Everything we hold falls into the categories below.
Enquiry form submissions
Your name, email address, and the brief you write describing what you want built. All three fields are required; nothing else is asked for. Anything further we learn about you comes from what you chose to put in the brief.
Correspondence
If you email us or we reply to your enquiry, we keep the thread so we can follow up and so there is a record of what was asked and answered. Where a conversation turns into a proposal, that proposal and its associated notes are kept as engagement records.
Technical request data
Serving a page necessarily involves your IP address, the requested URL, your browser and device type, and a timestamp. This is processed at the network and hosting layer to deliver the response and to protect the site from abuse. We do not build profiles from it.
Anti-abuse data on the form
The enquiry form is rate-limited to a small number of submissions per IP address per minute, which means an IP address and recent timestamps are held briefly in server memory. It also carries a hidden field that real people never see; if it is filled in, the submission is silently discarded as automated. Your IP address is included in the notification email so we can identify a source of abuse.
Your consent choice
The answer you give the cookie banner is stored in your own browser's local storage. It is never transmitted to us. See our Cookie Policy for the exact keys.
Engagement records
If you become a client, we hold the contact details of the people we work with, the contract documents, invoices, and the records our accountants and tax obligations require. These are ordinary business records rather than anything the site collects.
What We Do Not Collect
Worth stating explicitly.
Much of what a privacy policy usually has to explain simply does not happen here. To be unambiguous about it:
- No analytics — there is no Google Analytics, no Tag Manager, and no other measurement tool running on this site
- No advertising or tracking pixels, and no cross-site tracking of any kind
- No accounts or passwords — there is nothing on this site to sign in to
- No payment data — the site takes no payments; client invoicing happens by bank transfer outside the site
- No data brokers — we do not buy personal data, enrich records with purchased information, or append firmographic data to your enquiry
- No sale of personal data, and no sharing of it for cross-context behavioural advertising
- No newsletter or marketing list — we do not add you to a mailing list because you sent us a brief
- No special category data is requested at any point; please do not put health, biometric, political, religious, or similar information into the brief
Note
We also do not train machine-learning models on your brief or on client material, and we do not paste client confidential information into third-party AI tools.
How We Use Information
Every purpose, and no others.
- Answering your enquiry — reading your brief, replying to it, and having the follow-up conversation.
- Scoping and proposing work — turning a brief into an architecture, an estimate, and a Statement of Work.
- Delivering an engagement — communicating with your team and doing the work we were contracted to do.
- Business administration — invoicing, accounting, and keeping the records the law requires us to keep.
- Security and abuse prevention — rate-limiting the form, discarding automated submissions, and investigating misuse of the site.
- Legal compliance — meeting our tax and regulatory obligations and responding to lawful requests.
Note
We do not use your enquiry to market to you beyond replying to it. If you write to us once and we do not end up working together, you will not hear from us again unless you get back in touch.
Legal Bases for Processing
Why each use is lawful under the GDPR and UK GDPR.
If you are in the European Economic Area, the United Kingdom, or Switzerland, we must have a lawful basis for each purpose. Ours are:
- Steps prior to a contract, and performance of a contract (Art. 6(1)(b)) — answering your enquiry, preparing a proposal at your request, and then delivering and invoicing an engagement.
- Legitimate interests (Art. 6(1)(f)) — keeping the site available and free of abuse, retaining correspondence so we have a record of what was agreed, and holding engagement records for the ordinary running of the business. We have weighed these against your rights and collect the minimum each requires.
- Consent (Art. 6(1)(a)) — anything stored in your browser beyond what is strictly necessary. You give it through the banner and can withdraw it at any time, without affecting processing already carried out.
- Legal obligation (Art. 6(1)(c)) — retaining financial and tax records, and responding to valid legal process.
Objecting to legitimate interests
Where we rely on legitimate interests you have the right to object, and we will stop unless we can show compelling grounds that override your rights. Write to us and say so; you do not need to give a reason for an objection to direct marketing.
Client and Project Data
When we process personal data on your instructions.
During an engagement we may be given access to systems containing personal data about your customers, staff, or users. We treat that data as yours throughout.
We process it only on your documented instructions, only for the purposes of the engagement, and only by people who need it. Our staff and subcontractors are bound by confidentiality obligations that survive the engagement.
- Clients subject to the GDPR, UK GDPR, or a comparable regime should ask for a Data Processing Agreement before an engagement involving personal data begins
- We prefer to work against anonymised, masked, or synthetic data in development environments, and will ask for it wherever a project allows
- Access to production systems is requested only where necessary, used only for the engagement, and surrendered at handover
- At the end of an engagement we return or delete client data on request, subject to any retention the law requires of us
Important
Please do not give us access to live production data containing personal information without agreeing the basis for it in writing first. If personal data reaches us in a way neither of us planned, tell us and we will work with you to contain and delete it.
International Transfers
Where your data goes.
We are a United States company and our records are held in the United States. If you are outside the US, sending us an enquiry involves transferring your data there.
The United States has not been the subject of a general adequacy decision covering all transfers. Where a transfer from the EEA or UK requires a safeguard, we rely on the European Commission's Standard Contractual Clauses, and the UK Addendum where the UK GDPR applies, together with the additional measures appropriate to the small amount of data involved.
Our hosting provider operates a global edge network, so a page may be served to you from a location near you rather than from the United States. You can ask us for a copy of the transfer safeguards we rely on.
How Long We Keep Things
Retention periods, and what happens at the end of them.
We keep personal data only as long as it serves the purpose it was collected for, or as long as the law requires.
| Data | Kept for | Then |
|---|---|---|
| Enquiry that goes nowhere | Up to 24 months from your last message | Deleted from the mailbox |
| Enquiry that becomes an engagement | Kept with the engagement records | See below |
| Engagement records and correspondence | 7 years after the engagement ends | Deleted |
| Invoices and financial records | As required by US tax and accounting law, currently 7 years | Deleted |
| Rate-limit records | Roughly one minute, in server memory only | Discarded automatically |
| Client project data we process | Duration of the engagement | Returned or deleted at handover, on your instruction |
Why engagement records last as long as they do
Professional services carry a long tail of potential claims, and contract and limitation periods run for years after a project ends. Keeping the record of what was scoped, agreed, and delivered protects both sides if a question arises later.
Asking for earlier deletion
You can ask us to delete an enquiry at any time and we will, unless it has become part of a live engagement or we need it to defend a legal claim. Say so in an email and we will confirm when it is done.
Security
How the small amount of data we hold is protected.
We keep the attack surface small on purpose. A site with no database, no accounts, and no stored submissions has very little to lose in the first place — the enquiry form does not write to a database at all, it sends an email and forgets.
- The site is served over HTTPS, with traffic encrypted in transit
- Enquiry mail is submitted over an authenticated, TLS-protected SMTP connection
- Submissions are validated and length-limited, escaped before being rendered into the notification email, and stripped of line breaks that could be used to inject mail headers
- The form is rate-limited per IP address and screened for automated submission
- Mail credentials are held as runtime secrets and never reach the browser or the client bundle
- Access to the mailbox that receives enquiries is limited to the people who need it and protected by strong, unique credentials
Important
No system is perfectly secure, and email in particular is not a confidential channel. Do not send credentials, API keys, personal data about other people, or regulated data through the enquiry form. If something sensitive needs to reach us, ask and we will agree a proper method first.
If Something Goes Wrong
Breach notification.
If a personal data breach occurs and it is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority without undue delay and, where feasible, within 72 hours of becoming aware of it.
Where the risk to you is high, we will tell you directly and without undue delay, describing what happened, what data was involved, what we are doing about it, and what you can do to protect yourself.
Where we are acting as a processor for a client, we notify that client without undue delay so they can meet their own obligations, rather than notifying regulators or individuals ourselves.
Your Rights
What you can ask us to do.
If you are in the EEA, the UK, or Switzerland, the GDPR and UK GDPR give you the rights below. We extend the substance of them to everyone who writes to us, wherever they are, because operating two standards for a handful of records would be pointless.
- Access — a copy of the personal data we hold about you, and an explanation of what we do with it
- Rectification — correction of anything inaccurate or incomplete
- Erasure — deletion, where we have no overriding reason to keep it
- Restriction — a pause on processing while a dispute about accuracy or legitimate interests is resolved
- Portability — the data you gave us, in a structured, machine-readable format
- Objection — to processing based on legitimate interests, and absolutely to direct marketing
- Withdrawal of consent — at any time, without affecting processing already carried out
How to exercise them
Write to [email protected] saying what you want. We respond within 30 days, and will tell you if we need longer because a request is complex. There is no charge unless a request is manifestly unfounded or excessive.
Verifying who you are
We may need to confirm your identity before acting, which normally means replying from the email address the data is associated with. We will not ask you for identity documents to answer a request about an email address.
Complaining
You can complain to your local supervisory authority — in the UK, the Information Commissioner's Office; in the EEA, the authority for your country. We would rather you raised it with us first so we have a chance to put it right.
US State Privacy Rights
California, and other states with comparable laws.
Residents of California and of other states with comprehensive privacy laws — including Virginia, Colorado, Connecticut, Utah, and Texas — have rights to know, delete, correct, and obtain a portable copy of their personal information, and to be free from discrimination for exercising them.
We honour these requests through the same channel and the same timescales as the rights above.
We do not sell or share your personal information
Under the CCPA and CPRA definitions, we do not sell personal information and we do not share it for cross-context behavioural advertising. We have never done so, and there is accordingly no “Do Not Sell or Share My Personal Information” mechanism to offer — there is nothing for it to switch off.
Categories collected
In the twelve months preceding the date at the top of this page, we have collected identifiers (name, email address, IP address) and the content of any brief you chose to send. We disclosed these for business purposes only, to the recipients listed under Who We Share Information With.
Sensitive personal information
We do not request or intentionally collect sensitive personal information, and we do not use or disclose it for purposes requiring a right to limit.
Authorised agents
You may use an authorised agent to submit a request. We will ask for written proof of their authority, and may ask you to confirm it directly.
Children's Privacy
This is not a service for children.
This site is aimed at businesses and the people who run them. It is not directed at children, and we do not knowingly collect personal data from anyone under 16.
If you believe a child has sent us information through the enquiry form, tell us and we will delete it promptly.
Automated Decision-Making
There isn't any.
We do not carry out profiling or automated decision-making that produces legal or similarly significant effects. A human reads every enquiry and a human decides whether we take a project on.
The only automation touching your submission is the anti-spam check and the rate limit, which may cause a submission to be discarded or delayed. If you think a legitimate enquiry was blocked, email us directly and it will reach us.
Links to Other Sites
Where this policy stops applying.
The site links to our profiles on LinkedIn, Facebook, and Telegram, to our office address on Google Maps, and to UCN Mail and UCN VPN. Following any of those links takes you somewhere governed by someone else's policy.
Nothing loads from those services while you are on our pages, and we receive no notification that you followed a link. We are not responsible for their content or their privacy practices.
Changes to This Policy
How updates are made and communicated.
We may update this policy as the site or the business changes. The “Last updated” date at the top always reflects the most recent revision.
Where a change materially affects how we use data we already hold about you, and we have a way to reach you, we will tell you directly rather than relying on you to re-read this page.
Contact Us
How to reach us about privacy.
Questions about this policy, requests to exercise your rights, or anything else about how we handle personal data:
- Entity
- UCNHUB LLC
- Address
- 254 Chapman Rd, Suite 101-B
Newark, DE 19702, United States - Privacy contact
- [email protected]
- Response time
- Within 30 days, usually far sooner
- Related
- Cookie Policy · Terms & Conditions
